this post was submitted on 27 Jan 2026
834 points (99.6% liked)
Technology
79355 readers
4240 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
ok yea, I do agree with that POV on it. A ghost key like that would be within spec, cause yea at that point it would just be another member. I wasn't taking it as an additional group member though, since the whistleblower is stating that they can put in any user id and have access to all messages live, that would mean they would have a ghost user on all messages period regardless of if its a group chat or not.
That wouldn't be implausible though.
I will say, not too long ago there was some question if I had setup a WhatsApp account with my number due to some emails I was receiving. Not wanting to install the app and unwittingly create an account just by checking if I had one, my wife created a group chat with just her and my number, sent a message, and then we saw it get marked as read by all. Which in an E2EE system should not have been possible without me having the app setup. so I did go ahead and wiped an old and setup the app to make sure I was in control of any account for my number, and I did then receive that group chat. But still, very sketchy.